Rank #3 of 6 in Hardware Security Keys
Try itExperimental
See what an agent can do with Token2 before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/token2/fido2-managerecorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fidoevidence →
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper toolingevidence →
Building with and managing the key — CLIs, SDKs, attestation
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compatevidence →
Where the key works — platforms, browsers, service compatibility catalogs
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recoveryevidence →
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware opennessevidence →
What runs on the device — open-source firmware, update policy, vulnerability response
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet managementevidence →
Keys at organization scale — bulk provisioning, delivery services, IdP policies
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factorsevidence →
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverageevidence →
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Token2 stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
—0/10
Subscribe to events via webhooks
n/an/a
Build against official SDKs
—–
Issue scoped/least-privilege API credentials for an agent
n/an/a
Connect an agent via an official MCP server
n/an/a
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
n/an/a
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
n/an/a
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
n/an/a
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Keep OpenPGP keys on the device and use them for git commit signing and encrypted email
—–
The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
—0/10
The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
~5/10
My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
~6/10
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling
Building with and managing the key — CLIs, SDKs, attestation
An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
~5/10
Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
~3/10
Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
~6/10
Official SDKs let me integrate the key into my own desktop and mobile apps
—0/10
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat
Where the key works — platforms, browsers, service compatibility catalogs
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness
What runs on the device — open-source firmware, update policy, vulnerability response
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management
Keys at organization scale — bulk provisioning, delivery services, IdP policies
An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
~3/10
An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics
—–
The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
~4/10
Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
~5/10
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
—–
The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
—–
Tap the key on my phone over NFC to authenticate in mobile browsers and apps
~4/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | n/a | untested | none yet | |
The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username Fido2 | security engineer | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 3 | full | 8/10 | Tprobed | |
Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably Cli | developer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 3 | partial | 6/10 | Tprobed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 5/10 | Tprobed | |
Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys Provisioning | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 3 | partial | 5/10 | Tprobed | |
The vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost Recovery | security engineer | Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery | 3 | partial | 3/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | n/a | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate User verification | security engineer | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | full | 8/10 | Tprobed | |
List and delete the passkeys stored on my key and know its credential capacity before it fills up Credential management | power user | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | partial | 7/10 | Tprobed | |
First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts Setup | power user | Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery | 2 | partial | 6/10 | Cclaimed | |
My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch Ssh | developer | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | partial | 6/10 | Tprobed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 6/10 | Tprobed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers Fido2 | power user | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | partial | 6/10 | Cclaimed | |
An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet Agent audit | ai-native user | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | partial | 5/10 | Tprobed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 5/10 | Cclaimed | |
The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device Piv | it admin | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | partial | 5/10 | Cclaimed | |
The key works across my operating systems and browsers, with a published compatibility catalog of supported services Compatibility | power user | Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat | 2 | partial | 5/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 4/10 | Tprobed | |
Tap the key on my phone over NFC to authenticate in mobile browsers and apps Nfc | power user | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | partial | 4/10 | Cclaimed | |
The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication Idp | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | partial | 4/10 | Tprobed | |
An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console Agent provisioning | ai-native user | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | partial | 3/10 | Tprobed | |
Verify device attestation at registration to enforce that only genuine, approved key models are enrolled Attestation | security engineer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | partial | 3/10 | Cclaimed | |
Official SDKs let me integrate the key into my own desktop and mobile apps Sdks | developer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | none | 0/10 | ||
The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn Otp | power user | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | none | 0/10 | ||
An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics Delivery | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | none | untested | none yet | |
Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance) Certifications | it admin | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | none | untested | none yet | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Keep OpenPGP keys on the device and use them for git commit signing and encrypted email Openpgp | developer | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device Source | security engineer | Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness | 2 | none | untested | none yet | |
The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors Connectors | power user | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | none | untested | none yet | |
The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices Updates | security engineer | Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness | 2 | none | untested | none yet | |
Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions Agent approval | ai-native user | Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat | 1 | none | 0/10 | ||
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 38 stories with headroom
What would move Token2’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDrive the product through a documented public API
nonemoves agent-readyimpact 45
Token2 is a hardware security key vendor; probes explicitly show no public API, no OpenAPI/Swagger spec, and no llms.txt (404s across all checked endpoints).
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs
nonemoves agent-readyimpact 30
Direct probes show no llms.txt (404) and no markdown-accessible docs (404), and no OpenAPI/agent-oriented documentation exists; Token2 is a hardware security key vendor with no evidence of agent-discoverable docs.
Agenticness — how well agents can access and operate the productBuild against official SDKs
nonemoves agent-readyimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Token2 is a hardware security key vendor with no evidence of an API reference at all — the probes explicitly show no OpenAPI/swagger spec exists (404s across all candidate paths) and no llms.txt or docs.md exposure.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Token2 is a hardware security key vendor with desktop/browser tools and a CLI, but there is no evidence of a machine-readable API spec; explicit probes for OpenAPI/Swagger endpoints and llms.txt all returned 404.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Token2 is a hardware security key vendor with desktop/CLI tools for FIDO2/PIV management; there is no evidence of any versioned public API, and probes confirm no OpenAPI/Swagger spec exists (404s across all candidate paths).
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost
partialq3/10moves PA Scoreimpact 21
Missing: detailed recovery/lockout policy content, explicit statement of non-recoverable data (e.g., resident key private keys), and any independent corroboration of the backup-key workflow.
Showing the top 8 of 38 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 23 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
GitHub README20 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Perform bulk operations across many items at once
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
- Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
- The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
- Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Control data retention and deletion
- List and delete the passkeys stored on my key and know its credential capacity before it fills up
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
- The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate
Site docs19 stories
- Run the product headlessly / in CI for automation
- The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- The vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
- Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Control data retention and deletion
- List and delete the passkeys stored on my key and know its credential capacity before it fills up
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
- The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate
Tools docs6 stories
- Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
OpenAPI spec4 stories
- Run the product headlessly / in CI for automation
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
- Do everything through the API that I can do in the UI
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/token2/fido2-managereproduced$ curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/[redacted]2/fido2-manage
200 https://github.com/[redacted]2/fido2-manage
Business model
Hardware purchase, cheapest certified keys in the arena — Pico RP2350 key $8.08, KeyTen NFC $20.77, PIN+ Release3.3 with PIV and TOTP $25.39. Swiss vendor.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
